Resources
Data handling and security
Company Brain is a controlled validation prototype for limited operational material. Treat redaction and scope control as part of the trial process.
You should know what not to upload and which enterprise controls are not part of the current MVP.
Redaction is required
Remove secrets, payment details, regulated health or legal data, private employee records, highly confidential customer material, and unnecessary personal identifiers before upload unless suitable handling terms have been agreed.
What the hosted trial stores
- Application records, account records, and session records.
- Extraction run summaries, source-document metadata, and short text previews.
- Generated output packs, review edits, approval metadata, and final exports.
- Post-export debrief answers and internal trial credit ledger entries.
Current security boundaries
- Invite-only trial access can exist for controlled applicants.
- Passwords are hashed; plaintext passwords are not stored.
- The prototype does not provide enterprise retention controls, automated redaction, DLP scanning, SSO, RBAC, or a managed production database.
- Public application submissions are bounded by request size, basic per-client throttling, and recent duplicate email suppression.
Practical rule
Upload only what is needed to understand one issue. If a file exposes sensitive information unrelated to that issue, do not upload it.